CVE-2021-22749
Summary
| CVE | CVE-2021-22749 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-06-11 16:15:00 UTC |
| Updated | 2021-06-22 19:02:00 UTC |
| Description | A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Modicon X80 BMXNOR0200H RTU SV1.70 IR22 and prior that could cause information leak concerning the current RTU configuration including communication parameters dedicated to telemetry, when a specially crafted HTTP request is sent to the web server of the module. |
Risk And Classification
Problem Types: CWE-200
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Schneider-electric | Modicon X80 Bmxnor0200h Rtu | - | All | All | All |
| Operating System | Schneider-electric | Modicon X80 Bmxnor0200h Rtu Firmware | sv1.6 | ir4 | All | All |
| Operating System | Schneider-electric | Modicon X80 Bmxnor0200h Rtu Firmware | sv1.7 | ir10 | All | All |
| Operating System | Schneider-electric | Modicon X80 Bmxnor0200h Rtu Firmware | sv1.7 | ir15b | All | All |
| Operating System | Schneider-electric | Modicon X80 Bmxnor0200h Rtu Firmware | sv1.7 | ir17 | All | All |
| Operating System | Schneider-electric | Modicon X80 Bmxnor0200h Rtu Firmware | sv1.7 | ir18 | All | All |
| Operating System | Schneider-electric | Modicon X80 Bmxnor0200h Rtu Firmware | sv1.7 | ir19 | All | All |
| Operating System | Schneider-electric | Modicon X80 Bmxnor0200h Rtu Firmware | sv1.7 | ir20 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| download.schneider-electric.com/files | MISC | download.schneider-electric.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 590516 Schneider Electric Modicon X80 information disclosure Vulnerability (ICSA-21-159-05)